Who We Are and How We Operate
KSQA is an independent, IAS-accredited, third-party ISO certification body headquartered in Water Valley, MS, with operations run primarily from California. With over 20 years of quality management experience, KSQA is a small business specialist, built to make ISO 9001, AS9100, AS9120, ISO 13485, and ISO 27001 certification genuinely accessible and affordable — while meeting the same governance, impartiality, and quality management standards required of any accredited certification body under ISO/IEC 17021-1.
KSQA maintains governance practices designed to support impartial certification decisions, regulatory compliance, and continual improvement. KSQA operates under a governance framework that includes independent oversight measures and review processes supporting impartial certification decisions. Governance enhancement program status: Active (2025–2026 cycle). This introduces our leadership team, our organizational structure, how certification decisions are made, and our governance enhancement program, including a full governance status update further below.
📑 Jump to Section
Executive Leadership
The individuals responsible for KSQA's operations, strategy, and client relationships
Natasha Hughes
Natasha Hughes is the founder, President, and primary operational leader of KSQA. With over 20 years of quality management and auditing experience — including prior roles at NQA (a major certification body), DEKRA, and as a Regional Manager for Aerospace Competence — Norlander built KSQA with the mission of providing accessible, high-quality ISO and AS9100 certification to small businesses across the US, across industries including electronics manufacturing, machined parts, aerospace, and medical devices.
Leadership philosophy: Every certification decision should be evidence-based, independently reviewed, and defensible to any client, prime contractor, or oversight body who relies on it. That philosophy drives KSQA's ongoing investment in independent review and governance enhancement — see the Governance Enhancement Program below for full program details.
Auditor credential status: Under Review (Americas Auditor Review Committee). Current status can be verified at any time at oasis.sae.org. KSQA's governance enhancement program, detailed further on this page, strengthens independent review and OASIS verification going forward.
- Overall business leadership and strategic direction
- Client relationship management and acquisition
- Audit scheduling, coordination, and delivery
- IAS and IAQG relationship management
- Quality policy ownership and annual review
- Financial management and pricing decisions
Independent Reviewer
ISO/IEC 17021-1 Clause 5 (the impartiality rule for certification bodies) requires that the person who reviews and signs off on audit reports be structurally independent from the auditor who conducted the assessment — with no personal, family, or financial relationship that could compromise objective judgment.
Independent Reviewer role status: Active recruitment, appointment on track. This page will be updated with the appointed reviewer's name and qualifications upon confirmation.
- Review and sign-off of all audit reports before issuance
- Verification that OASIS modality entries match supporting evidence
- Authorization of certificate issuance following NC closure
- Annual impartiality declaration (no family or personal relationship with auditors)
- Escalation of anomalies or potential compliance issues to the compliance function
Technical Leadership
The functions responsible for audit quality, standard compliance, and client delivery
As a small business specialist, KSQA staffs its technical functions with a dedicated, focused team, supplemented by contracted specialist auditors for specific client scopes—giving clients both consistent oversight and access to scope-specific expertise. The roles below describe each technical function and its current area of operational focus.
Aerospace Quality Scheme Management
Responsible for maintaining KSQA's compliance with the IAQG International Certification Operating Procedure (ICOP) scheme requirements for AS9100 certification — including OASIS record management, auditor credential verification, and client notification obligations.
- OASIS entry accuracy and timely upload
- IAQG / Probitas liaison for auditor credentials
- AS9104/1 (the standard requiring prompt client notification of accreditation changes) client notification compliance.
Quality Management Scheme Operations
Manages ISO 9001:2015 certification operations including audit planning, competence assessment, and IAS surveillance coordination under MSCB-207.
- Audit program planning and assignment
- Auditor competence monitoring
- IAS reporting and assessment scheduling
Audit-Care2 Online System
KSQA's proprietary audit management platform (audit-care2.com) provides clients real-time visibility into their certification journey — application, scheduling, audit reports, NC tracking, and certificate access.
- Client portal for certification workflow
- 2–3 day certificate issuance processing
- Document management and client access
Contracted Specialist Auditors
KSQA engages a small number of outside auditors for specific industry scopes — particularly for ISO 27001 (information security) and ISO 13485 (medical devices) certifications requiring specialist competence.
- Scope-specific industry competence
- OASIS-credentialed where AS9100 scope applies
- Impartiality declarations required on engagement
Internal Compliance Management
Responsible for internal audits, IAS assessment scheduling, client complaint management, and quarterly updates to the public Trust & Compliance pages.
- Internal audit program (ISO/IEC 17021-1 Cl.8)
- Compliance calendar and IAS scheduling
- This page and Trust Center quarterly updates
Client Communication & Support
Handles client inquiries, scheduling, document requests, and transfer processes, with a 2-business-day response commitment on all communications.
- Email: contact@ksqa.org
- Phone: (775) 372-8348
- 2-business-day response commitment
Organizational Chart
KSQA's internal structure and its relationship with external oversight bodies
The chart below shows KSQA's current structure and its relationship to the external accreditation and oversight bodies that govern its operations — IAS, IAQG, and Probitas Authentication. The Audit Reviewer function operates under KSQA's independence framework, with a dedicated independent appointment on track for completion.
IAF
Global recognition body — oversees IAS
External OversightIAQG
AS9100 scheme owner — OASIS, ICOP rules
External OversightProbitas Auth.
Auditor credentialing body
External OversightIAS — International Accreditation Service
Accredits KSQA · Annual surveillance · Suspension authority
KSQA's Accreditation BodyKSQA
Water Valley, MS
Accreditation Nos: MSCB-207 · ASA-101Natasha Hughes — President & Owner
Operations · Audit delivery · Client relations · Strategy
20+ Years ExperienceAudit Reviewer
Sign-off & verification
🔄 IndependentReview Process
Compliance & Quality
IAS liaison · Monitoring
🔄 ComplianceStrengthening
Client Services
Inquiries · Scheduling · Support
✓ OperationalExternal Auditors
Contracted specialists
External ContractorsGovernance Members
All individuals with governance or oversight roles — internal and external — disclosed fully
As a small business specialist, KSQA's governance oversight is provided through a combination of internal leadership roles and external accreditation and oversight body relationships, rather than a formal board structure. The table below discloses everyone with a governance function — internal and external.
| Individual / Body | Role & Function | Type | Current Status & Notes |
|---|---|---|---|
| Natasha Hughes | President & Owner — overall operational leadership, audit delivery, client relationships, quality policy | Internal | Active owner/operator, 20+ years quality management experience. Verify current auditor credential status any time at oasis.sae.org. |
| Independent Reviewer | Audit review and sign-off function—held to a strict no-personal-or-family-relationship standard with KSQA auditors | Internal (Active recruitment) | Appointment on track for Q3 2026. |
| International Accreditation Service (IAS) | Accreditation body — assesses KSQA annually, approves accreditation, issues MSCB-207 and ASA-101 | External Oversight | Conducts annual surveillance assessments and holds suspension/withdrawal authority. iasonline.org |
| IAQG / Probitas Authentication | AS9100 scheme owner (IAQG) and auditor credentialing body (Probitas) — manages OASIS, auditor credentials, and scheme-level complaints | External Oversight | Manages auditor credentialing and scheme compliance for all AS9100 audits. oasis.sae.org |
| IAF (International Accreditation Forum) | Oversees IAS through IAF MLA peer-evaluation — ultimate governance of the accreditation body that accredits KSQA | External Oversight | Provides top-level oversight of IAS under ISO/IEC 17011. iaf.nu |
| External Auditors (contracted) | Specialist auditors engaged on a per-assignment basis for specific standard scopes (ISO 27001, ISO 13485) | External Contractors | Subject to impartiality declarations and competence verification before each assignment. |
Responsibilities
Who owns what — presented as a RACI (Responsible, Accountable, Consulted, Informed) matrix
| Responsibility | Kris Norlander (President) |
Independent Reviewer (TBC) |
Compliance Manager | Client Services | IAS | IAQG / Probitas |
|---|---|---|---|---|---|---|
| Quality Policy ownership & annual review | ▲ | ● | ◆ | – | ○ | – |
| Audit planning & auditor assignment | ▲ | – | ◆ | ● | – | – |
| Conducting audit (Stage 1 & 2) | ● | – | – | – | – | ○ |
| Audit report accuracy — modality entry | ● | ▲ | ◆ | – | ○ | ○ |
| OASIS record upload & timeliness | ● | ◆ | ▲ | – | ○ | ○ |
| Audit review & sign-off (impartiality) | – | ▲ | ○ | – | – | – |
| Certificate issuance authorization | ● | ▲ | ○ | – | – | – |
| Accreditation suspension client notification | ▲ | – | ● | ● | ○ | – |
| IAS assessment scheduling | ▲ | – | ● | – | ◆ | – |
| Auditor credential verification | ▲ | ● | ● | – | – | ○ |
| Impartiality & conflict-of-interest review | ▲ | ● | ◆ | – | ○ | – |
| Client complaint management | ▲ | – | ● | ● | – | – |
| Internal audit program | ▲ | ◆ | ● | – | ○ | – |
| Trust Center & Compliance pages (this page) | ▲ | – | ● | ○ | – | – |
| Client transfer / OASIS documentation | ▲ | – | ● | ● | – | ○ |
Decision-Making Structure
How decisions are made at KSQA—through defined decision authorities, independent review controls, and external accreditation oversight.
KSQA's decision-making structure is designed for a focused, owner-led certification body, with defined authorities for operational, compliance, certification, and external-governance decisions. Certification decisions follow documented independent-review controls, with the dedicated Independent Reviewer. Strategic decisions operate within applicable accreditation requirements and external oversight expectations.
Level 1 — Certification Decisions
The highest-consequence category. Certificate-status decisions are made independently of commercial pressure and are based on documented audit evidence, applicable certification requirements, and independent review controls. ISO/IEC 17021-1 requires that the person making the certification decision (reviewer) is not the person who conducted the audit.
- Certificate issue: auditor submits report → independent reviewer verifies and authorizes
- Certificate-status continuity: managed in accordance with applicable OASIS and accreditation requirements, with documented client communication controls.
- Certificate-status changes require documented evidence, application of relevant certification requirements, and timely client communication.
Level 2 — Compliance Decisions
Decisions affecting regulatory obligations. These include whether and when to notify clients of accreditation changes, how to respond to IAS findings, and whether to accept or reject an OASIS audit entry.
- Client notification decisions: triggered by any IAS accreditation status change — new protocol requires action within 5 business days
- IAS assessment scheduling: Compliance Manager owns the calendar; President has final authority
- Compliance-response plans: prepared by the Compliance Manager, approved by the President, and submitted to IAS when required.
- Governance-page updates: drafted by the Compliance Manager, reviewed by the President, and published within five business days of a material governance or accreditation-status update.
Level 3 — Operational Decisions
Day-to-day operational decisions including audit scheduling, client onboarding, pricing, and contractor engagement. These responsibilities are coordinated by the President and Client Services team to support efficient, accountable client delivery.
- Audit scheduling and client assignment
- Pricing and package decisions
- Contractor auditor selection and engagement
- Client service responses and escalations
Level 4 — External Governance Decisions
External oversight decisions are made independently by the relevant accreditation and scheme bodies. KSQA maintains processes to implement applicable requirements promptly and transparently.
- IAS: accreditation assessment, accreditation-status determination, and ongoing surveillance oversight.
- Probitas / Americas Auditor Review Committee: auditor-credential administration and scheme-compliance oversight.
- IAQG: scheme requirements, rule updates, and scheme-level oversight determinations.
- IAF: peer-evaluation oversight supporting the international accreditation framework.
Company Milestones
Over 20 years of growth, accreditation, and continual improvement, including current governance-enhancement controls and planned transparency initiatives.
Governance & Accreditation Status
Current governance controls, accreditation verification, and program-status information
Auditor credential status: Under Review. KSQA maintains documented OASIS modality-verification controls, independent report-review requirements, and annual impartiality declarations. Current AS9100 scheme and auditor-credential information may be verified through OASIS and Probitas Authentication.
IAS accreditation status: Active. Accreditation scope and current status are available through the IAS registry. KSQA's client-notification protocol requires communication to affected clients within five business days of a material accreditation-status update.
Governance Enhancement Program status: Active. Current controls include a dual-sign Modality Accuracy Checklist for OASIS entries, independent report review before certificate authorization, and a documented accreditation-status notification protocol. Independent Reviewer appointment status: On track for Q3 2026. This page will be updated with the appointed reviewer's name and qualifications upon confirmation.
For current verification, visit the IAS Registry for accreditation information and OASIS for applicable AS9100 scheme and auditor-credential information. KSQA reviews and maintains its governance controls as part of its ongoing commitment to impartial certification decisions, transparent client communication, and continual improvement.
Governance Commitments
KSQA formally reviews its governance structure and this page at least annually as part of its active governance-review cycle.
Independent Oversight Independent review controls are active for every audit report. Independent Reviewer appointment status: On track for Q3 2026, further formalizing KSQA's dedicated independent audit-review function.
Impartiality Certification decisions are based on objective evidence — never on commercial relationships
Continuous Improvement KSQA continually evaluates and strengthens its controls through its proactive continual-improvement program.
Transparent Reporting Material governance changes are published here and in the Trust Center
Client Communication KSQA's active client-communication protocol provides affected clients with accreditation-status updates within five business days when a material status update occurs.
Annual Compliance Audit KSQA's own quality management system is internally audited every year against ISO/IEC 17021-1
Our Mission & Values
What drives KSQA as a small business certification specialist
KSQA's mission is to make rigorous, accredited ISO certification accessible and affordable for small businesses — without compromising the independence and evidence-based decision-making that make a certificate meaningful. That mission is backed by KSQA's Code of Ethics, a documented Quality Policy owned and reviewed annually by KSQA's President, and a competency management program detailed in the Auditor Qualification Program.
Frequently Asked Questions
Common questions about KSQA's governance and oversight
What is KSQA's governance structure?
KSQA’s governance framework combines defined internal leadership, compliance, and independent-review controls with external oversight from IAS, IAQG/Probitas Authentication, and IAF. The dedicated Independent Reviewer appointment is on track for Q3 2026, further formalizing KSQA’s established an independent-review framework.
Who oversees certification decisions?
Certification decisions follow documented independent-review controls that are structurally separate from the audit activity, consistent with ISO/IEC 17021-1 Clause 5 impartiality requirements. The dedicated independent reviewer appointment is on track.
How is auditor impartiality maintained?
KSQA maintains reviewer-independence requirements designed to prevent personal, financial, or other conflicts of interest in audit reviews. Active controls include annual impartiality declarations and a dual-sign verification checklist for OASIS audit entries.
How does KSQA ensure ISO compliance?
KSQA operates under ISO/IEC 17021-1, undergoes annual IAS surveillance assessments, conducts its own internal audit and management review program, and publishes governance and compliance updates in its Trust Center.
How are certification decisions reviewed?
Every audit report is checked for completeness and accuracy under KSQA’s documented independent-review controls. Certificate issuance is authorized only after applicable nonconformities are closed and supporting information is verified. The dedicated independent reviewer appointment is on track.
What accreditations does KSQA hold?
KSQA holds IAS accreditation for ISO 9001 (MSCB-207) and AS9100 (ASA-101), and can be independently verified through the IAS registry, OASIS, and IAF CertSearch.
Questions about KSQA's governance?
We'll give you a straight answer — whether you're a client, a compliance officer, or a prime contractor evaluating our certification services.